2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18266MEDIUM5.4Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose ...
CVE-2026-16553MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2...
CVE-2026-15831MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that u...
CVE-2026-15077MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that u...
CVE-2026-14351MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19...
CVE-2026-14341MEDIUM4.9GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-13113MEDIUM5.3GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2...
CVE-2026-13346MEDIUM5.6pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo...
CVE-2026-59920MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...
CVE-2026-59919MEDIUM5.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...
CVE-2026-59900MEDIUM5.3Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54705MEDIUM6.3MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten...
CVE-2026-13723MEDIUM6.5A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar...
CVE-2026-20316MEDIUM5.3A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti...
CVE-2026-18257MEDIUM5.6Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert...
CVE-2026-16729MEDIUM6.5undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before ...
CVE-2026-15144MEDIUM5.3@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec...
CVE-2026-67193MEDIUM6.9Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to...
CVE-2026-54082MEDIUM6.5veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve...
CVE-2026-54081MEDIUM6.9veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service...
CVE-2026-54080MEDIUM6.9veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service...
CVE-2026-50558MEDIUM5.9Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d...
CVE-2026-17550MEDIUM5.5A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili...
CVE-2026-66724MEDIUM5.3MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u...
CVE-2026-54663MEDIUM6.1swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now